Capabilities

Everything a connected AI app can do in your workspace, and the permission each one needs.

When you approve a connection you choose which of two permissions to grant:

PermissionCovers
ViewEverything under Reading below.
Create and updateEverything under Writing below.

Grant view only and every writing capability is refused, with a message saying it needs write access.

Every capability below takes an optional workspace β€” say which one you mean and it runs there; say nothing and it runs in the connection's default. Two capabilities exist just for that:

CapabilityWhat it does
List workspacesEvery workspace you belong to, with your role in each and which one is the default.
Set default workspaceChanges the default for this connection β€” "switch to Acme". It stays changed until you change it again.

Reading

Finding your way around

CapabilityWhat it does
Get workspace hierarchyReturns the tree β€” spaces, their folders and subfolders, and the projects in each. This is how the app learns what exists before doing anything else.
List membersThe people in the workspace, with their roles. Used to work out who to assign a task to when you name someone.
Get docs hierarchyThe documents tree β€” folders, pages and sub-pages you have access to.

Tasks

CapabilityWhat it does
List tasksOpen tasks, optionally just yours or just one project's.
Get taskThe full detail of one task β€” description, status, priority, dates, project, assignees.
List overdue tasksOpen tasks past their due date, most overdue first, reckoned in your workspace's timezone.
Search tasksFinds tasks by title, across the workspace or within one project β€” for when you refer to a task by name.
Get task commentsReads a task's comment thread, with author names.

Docs

CapabilityWhat it does
Search docsFinds document pages by title, with the document each belongs to.
Read doc pageReads a page's content, so the app can summarise or answer questions from it.

Chat

CapabilityWhat it does
List conversationsYour channels and direct messages, most recently active first.
List chat messagesReads the recent messages in one channel or direct message, oldest first, with sender names β€” so an app can catch you up or summarise a thread. Only conversations you belong to.

Time tracking

CapabilityWhat it does
Get time entriesThe time logged on a task, by whom, with the total β€” or, with no task named, your own recent entries and whether a timer is running right now. Someone else's timer stays private until they stop it.

Attendance, time off and the audit log

The workspace's people data. Each of these carries the same permission it carries in the app, so an app asking on behalf of someone without it is refused rather than answered.

CapabilityWhat it doesNeeds
Get attendance β€” dayWho worked on a given day: check-in and check-out, break and worked time, overtime, and whether the punch was off-site. Defaults to today in your workspace's timezone.Attendance access
Get attendance β€” memberOne person's day-by-day record over a range, with the same totals the PDF export carries. Defaults to the last 30 days.Attendance manager
Get attendance β€” teamPer-person totals over a range for the whole roster β€” days worked, hours, overtime.Attendance manager
Get time offYour own balances for the year and your requests β€” or, for whoever reviews leave, the whole approval queue with how much paid allowance each person has left.Membership for your own; the time-off approval permission for the queue
Get audit logRecent events in the workspace β€” who did what, to which item, and when. The answer to "who deleted that project". Audit logs are Enterprise; on other plans nothing is recorded, and the app is told that rather than shown an empty list.The audit log permission β€” owner only unless an owner has switched admins on

Ranged attendance needs the manager permission here

Over a connection, reading a stretch of attendance needs the attendance manager permission β€” including for your own days. That is stricter than the app itself, where you can always look back over your own record. Nothing is exposed that would not be; you may just have to open Kokar for it.

Writing

Tasks

CapabilityWhat it doesNeeds
Create taskAdds a task to a project, with description, status, priority, dates and assignees.Create access to the project
Create subtaskAdds a subtask under an existing task, in the same project.Create access to the project
Update taskChanges an existing task. Only the fields mentioned change; status is set by its name on the board, e.g. "In Progress".Edit access β€” or being the assignee, for status and assignee changes on your own task
Delete taskSends a task to Trash, where it can be restored β€” same as deleting it in the app.Full-edit access to the project. Having created the task does not stand in for it, and workspaces that limit people to deleting their own work apply here too
Add tagTags a task, creating the tag if it does not exist yet.Edit access to the project β€” plus permission to manage tags, if the tag has to be created
Add commentPosts a comment on a task, under your name.Comment access to the task's project

Structure

CapabilityWhat it doesNeeds
Create spaceAdds a top-level space.Permission to create spaces
Create folderAdds a folder in a space, optionally nested inside another folder.Create access to the space
Create projectAdds a project (task board) in a space, optionally inside a folder.Create access to the space β€” and, when you name a folder, create access to that folder as well

Your plan's limits on how many spaces, folders and projects a workspace may hold apply here exactly as they do in the app. A connection is not a way around them.

Docs and chat

CapabilityWhat it doesNeeds
Create doc pageCreates a document page, optionally nested under another page.Permission to create docs
Update doc pageAdds to the end of a page, rewrites it, and/or renames it. Adding is the default; a full rewrite is only done when you ask for one.Edit access to the page
Send chat messagePosts to a channel you belong to, as you.Membership of the channel
Send direct messageSends a 1:1 message to a member, starting the conversation if there isn't one.Membership of the workspace

Time tracking

CapabilityWhat it doesNeeds
Start timerStarts a live timer on a task, for you. One timer runs at a time, and a forgotten one stops itself after 12 hours β€” the same rules as the app.Read access to the task
Stop timerStops your running timer and records the elapsed time on its task.Read access to the task
Log timeRecords work that already happened β€” minutes, an optional day and note, up to 24 hours per entry. Defaults to today in your workspace's timezone.Read access to the task

Everything is written as you

Chat messages and comments an AI app posts appear under your name, with no marking to say a machine wrote them, and time it logs is logged as your time. Read what it is about to send before you approve it.

What is deliberately not here

  • No permission or billing changes. Roles, invitations, plans and payment details cannot be touched over a connection.
  • No clocking in or out, and no correcting attendance. Attendance can be read by the people entitled to read it, never written. Office check-in depends on being where you say you are, and a connection would go around that.
  • No approving or denying time off. The queue can be read; the decision stays with a person in the app.
  • No permanent deletion. Deleting sends things to Trash; emptying Trash is something you do in the app.
  • No access to a workspace you are not a member of, and no way to ask for one β€” an AI app cannot even find out whether such a workspace exists.
  • No reading of private locations you are not a member of. The one exception is the workspace owner, whose connection can reach private items for the same reason they can in the app β€” somebody has to be able to.
  • No reading of chat you are not in. This one has no exception at all: a connection can only ever see the rooms and direct messages you belong to, and that is as true of the owner's connection as anyone's.

Frequently asked questions

Can a connected AI app see my whole workspace?

Only the parts you can see. It acts as you, so the same space, project and folder permissions apply, and private locations you are not a member of stay invisible. Chat is stricter still β€” only the rooms and direct messages you are actually in, with no exception for anyone.

Can an AI app read attendance, time off or the audit log?

Only if you can. Those reads carry the same permission they carry in the app β€” the day overview needs attendance access, ranged attendance reports and the time-off approval queue need the manager permission, and the audit log needs the audit permission, which starts out with the owner alone and is an Enterprise feature besides. Someone without them gets a message saying so, which is the same nothing the app shows them.

Can it clock me in or approve time off?

No. Clocking in and out is yours to do in the app, on purpose β€” office check-in is tied to where you actually are, and a connection would go around that. Approving and denying time off stays in the app too.

Keep reading